WordPress vs WP Engine, and the Internet Archive is down • Graham Cluley – Go Health Pro

WordPress vs WP Engine, and the Internet Archive is down • Graham Cluley – Go Health Pro

WordPress’s emperor, Matt Mullenweg, demands a hefty tribute from WP Engine, and a battle erupts, leaving millions of websites hanging in the balance. Meanwhile, the Internet Archive, a digital library preserving our online history, is under siege from hackers. All this and more is discussed in the latest edition of the “Smashing Security” podcast by … Read more

Jetpack patches critical bug that exposed data on 27M WordPress sites – Go Health Pro

Jetpack patches critical bug that exposed data on 27M WordPress sites – Go Health Pro

Jetpack released a patch for a critical vulnerability that could let malicious users submit a specially crafted request to the WordPress server to then disclose data submitted by other users — a flaw that left sensitive personal information potentially exposed on 27 million websites. Owned by Automattic, the company behind WordPress, the Jetpack plug-in offers … Read more

WordPress Mandates Two-Issue Authentication for Plugin and Theme Builders – Go Well being Professional

WordPress Mandates Two-Issue Authentication for Plugin and Theme Builders – Go Well being Professional

Sep 12, 2024Ravie LakshmananNet Safety / Content material Administration WordPress.org has introduced a brand new account safety measure that can require accounts with capabilities to replace plugins and themes to activate two-factor authentication (2FA) mandatorily. The enforcement is anticipated to return into impact beginning October 1, 2024. “Accounts with commit entry can push updates and … Read more

Crucial Safety Flaw Present in LiteSpeed Cache Plugin for WordPress – Go Well being Professional

Crucial Safety Flaw Present in LiteSpeed Cache Plugin for WordPress – Go Well being Professional

Sep 06, 2024Ravie LakshmananWordPress / Webinar Safety Cybersecurity researchers have found one more crucial safety flaw within the LiteSpeed Cache plugin for WordPress that would permit unauthenticated customers to take management of arbitrary accounts. The vulnerability, tracked as CVE-2024-44000 (CVSS rating: 7.5), impacts variations earlier than and together with 6.4.1. It has been addressed in … Read more

Essential WPML Plugin Flaw Exposes WordPress Websites to Distant Code Execution – Go Well being Professional

Essential WPML Plugin Flaw Exposes WordPress Websites to Distant Code Execution – Go Well being Professional

Aug 28, 2024Ravie LakshmananWordPress Safety / Web site Safety A important safety flaw has been disclosed within the WPML WordPress multilingual plugin that might enable authenticated customers to execute arbitrary code remotely beneath sure circumstances. The vulnerability, tracked as CVE-2024-6386 (CVSS rating: 9.9), impacts all variations of the plugin earlier than 4.6.13, which was launched … Read more

x